Menu

Quote

Multiple vulnerabilities have been fixed in the Amanda backup system. CVE-2022-37703

Multiple vulnerabilities have been fixed in bluez library, tools and daemons for using Bluetooth devices. CVE-2021-3658

https://security-tracker.debian.org/tracker/DSA-5767-1

Integer overflows have been fixed in aom, an AV1 Codec Library. For Debian 11 bullseye, this problem has been fixed in version 1.0.0.errata1-3+deb11u2.

* bsc#1221243 * bsc#1221677 * bsc#1224117 Cross-References:

* bsc#1229821 Cross-References: * CVE-2024-8381 * CVE-2024-8382

* bsc#1229013 Cross-References: * CVE-2024-7348

* bsc#1229013 Cross-References: * CVE-2024-7348

* bsc#1229869 Cross-References: * CVE-2023-45288

* bsc#1217353 Cross-References: * CVE-2023-5752

Sinatra is an open source web framework for Ruby programming language. CVE-2022-29970

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

https://security-tracker.debian.org/tracker/DSA-5766-1

* bsc#1229823 * bsc#1229824 Cross-References: * CVE-2024-45230

* bsc#1228046 * bsc#1228047 * bsc#1228048 * bsc#1228050 * bsc#1228051

Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code.

Several security issues were fixed in Twisted.

* bsc#1176492 Cross-References: * CVE-2014-10401 * CVE-2014-10402

Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code.

https://security-tracker.debian.org/tracker/DSA-5765-1

It was discovered that there was a series of integer overflow vulnerabilities in LibTomMath, a multiple-precision mathematics library.

A vulnerability was discovered in Nokogiri, an open source XML and HTML library for Ruby. An inefficient regular expression was susceptible to excessive backtracking when attempting to detect encoding in HTML documents. This could lead to denial-of-service.

Multiple vulnerabilities were discovered in git, a fast, scalable and distributed revision control system. CVE-2019-1387

* bsc#1224044 Cross-References: * CVE-2024-34397

Path traversal that allowed TZInfo::Timezone.get to load arbitrary files has been fixed in ruby-tzinfo, a Ruby library for working with time zone information.

Fix buffer overrun when giving an offset to Session:receive

https://security-tracker.debian.org/tracker/DSA-5764-1

Several security issues were fixed in Dovecot.

patchlevel 703 Security fixes for CVE-2024-43374, CVE-2024-43802

Update to upstream 2.1-44. 20240813 Update of 06-55-07/0xbf (CLX-SP/W/X B1/L1) microcode from revision 0x5003605 up to 0x5003707; Update of 06-55-0b/0xbf (CPX-SP A1) microcode from revision 0x7002802 up to 0x7002904;

New libpcap packages are available for Slackware 15.0 and -current to fix security issues.

Update to upstream 2.1-44. 20240813 Update of 06-55-07/0xbf (CLX-SP/W/X B1/L1) microcode from revision 0x5003605 up to 0x5003707; Update of 06-55-0b/0xbf (CPX-SP A1) microcode from revision 0x7002802 up to 0x7002904;

Security fix for CVE-2024-8088

error handling in x86 IOMMU identity mapping [XSA-460, CVE-2024-31145] PCI device pass-through with shared resources [XSA-461, CVE-2024-31146]

error handling in x86 IOMMU identity mapping [XSA-460, CVE-2024-31145] PCI device pass-through with shared resources [XSA-461, CVE-2024-31146]

https://security-tracker.debian.org/tracker/DSA-5761-1

The following vulnerabilities have been discovered in the WebKitGTK web engine: CVE-2024-4558

An update that fixes four vulnerabilities is now available.

An update that fixes three vulnerabilities is now available.

An update that fixes three vulnerabilities is now available.

* bsc#1227052 Cross-References: * CVE-2024-6104

An update that fixes four vulnerabilities is now available.

Security fix for CVE-2024-8088

Security issues were discovered in Chromium which could result in the execution of arbitrary code, denial of service, or information disclosure.

https://security-tracker.debian.org/tracker/DSA-5763-1

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

* bsc#1227353 Cross-References: * CVE-2024-39884

Security fix for CVE-2024-32487 – less with LESSOPEN mishandles n in paths

https://security-tracker.debian.org/tracker/DSA-5760-1

Several security issues were fixed in the Linux kernel.

* bsc#1228696 * bsc#1228697 * bsc#1228698 Cross-References:

CVE-2024-23184: A large number of address headers in email resulted in excessive CPU usage. CVE-2024-23185: Abnormally large email headers are now truncated or discarded, with a limit of 10MB on a single header and 50MB for all the headers of all the parts of an email.

CVE-2024-23184: A large number of address headers in email resulted in excessive CPU usage. CVE-2024-23185: Abnormally large email headers are now truncated or discarded, with a limit of 10MB on a single header and 50MB for all the headers of all the parts of an email.

* bsc#1210619 * bsc#1220145 * bsc#1220537 * bsc#1222685 * bsc#1223059

* bsc#1225202 * bsc#1225302 Cross-References: * CVE-2021-47378

* bsc#1210619 * bsc#1223363 * bsc#1223683 * bsc#1225013 * bsc#1225202

* bsc#1226463 * bsc#1227138 Cross-References: * CVE-2024-5535

* bsc#1225202 Cross-References: * CVE-2021-47378

* bsc#1225202 * bsc#1225302 Cross-References: * CVE-2021-47378

Multiple security issues were discovered in Python, a high-level, interactive, object-oriented language: CVE-2024-0397

* bsc#1225983 Cross-References: * CVE-2024-21096

* bsc#1225202 Cross-References: * CVE-2021-47378

https://security-tracker.debian.org/tracker/DSA-5759-1

* bsc#1027519 * bsc#1227355 * bsc#1228574 * bsc#1228575

Several vulnerabilities were discovered in Apache Traffic Server, a reverse and forward proxy server, which could result in denial of service or request smuggling.

Security: processing of a specially crafted mp4 file by the ngx_http_mp4_module might cause a worker process crash (CVE-2024-7347). Thanks to Nils Bars.

Security: processing of a specially crafted mp4 file by the ngx_http_mp4_module might cause a worker process crash (CVE-2024-7347). Thanks to Nils Bars.

Security: processing of a specially crafted mp4 file by the ngx_http_mp4_module might cause a worker process crash (CVE-2024-7347). Thanks to Nils Bars.

Security: processing of a specially crafted mp4 file by the ngx_http_mp4_module might cause a worker process crash (CVE-2024-7347). Thanks to Nils Bars.

https://security-tracker.debian.org/tracker/DSA-5758-1

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Security issues were discovered in Chromium which could result in the execution of arbitrary code, denial of service, or information disclosure.

* bsc#1224188 Cross-References: * CVE-2021-36386

* bsc#1129596 Cross-References: * CVE-2019-9656

An update that fixes 20 vulnerabilities is now available.

* bsc#1228574 * bsc#1228575 Cross-References: * CVE-2024-31145

* bsc#1226316 * bsc#1228648 Cross-References: * CVE-2024-6600

* bsc#1219559 * bsc#1221563 Cross-References: * CVE-2023-52425

* bsc#1228613 * bsc#1228693 * bsc#1228694 * bsc#1228695 * bsc#1228696

Bump to version 5.9.4

https://security-tracker.debian.org/tracker/DSA-5757-1

* bsc#1224044 Cross-References: * CVE-2024-34397

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in QEMU.

Fix web process cache suspend/resume when sandbox is enabled. Fix accelerated images disappearing after scrolling. Fix video flickering with DMA-BUF sink. Fix pointer lock on X11. Fix movement delta on mouse events in GTK3.

Several security issues were fixed in the Linux kernel.

* bsc#1177179 Cross-References: * CVE-2020-26159

* bsc#1228574 * bsc#1228575 Cross-References: * CVE-2024-31145

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: